Search

Found 17,329 results in 3407ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-6057 critical 9.8 9.8 2mo ago FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.
CVE-2026-6024 critical 9.8 9.8 2mo ago A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. …
CVE-2026-6003 low 2.4 2.4 2mo ago A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /admin/user.php. Such manipulation of the argument f…
CVE-2026-5393 critical 9.1 9.1 FIX debian debian wolfssl 2mo ago Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-of-bounds read can occur on crafted input. This can only occur when --enable-ex…
CVE-2026-4631 critical 10.0 EXPFIX rheldebian debian sles 2mo ago Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit…
CVE-2026-5264 critical 9.8 9.8 FIX debian debian wolfssl 2mo ago Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that triggers a heap buffer overflow.
CVE-2026-29145 critical 9.5 FIX slesdebian debian 2mo ago CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0…
CVE-2026-5974 critical 9.8 9.8 deepwisdom 2mo ago FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
CVE-2026-5973 critical 9.8 9.8 deepwisdom 2mo ago FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
CVE-2026-5972 critical 9.8 9.8 deepwisdom 2mo ago FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
CVE-2026-5194 critical 9.1 9.1 FIX debian debian wolfssl 2mo ago Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accepted by signature ver…
CVE-2026-40089 critical 9.9 9.9 sonicverse 2mo ago Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API …
CVE-2026-28205 critical 9.8 9.8 2mo ago OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API.
CVE-2026-5971 critical 9.8 9.8 deepwisdom 2mo ago A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Exe…
CVE-2026-5970 critical 9.8 9.8 deepwisdom 2mo ago MetaGPT has an Injection issue
CVE-2026-5962 critical 9.8 9.8 2mo ago A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The manipulation results in path traversal. The attack m…
CVE-2025-62718 critical 9.9 9.9 FIX slesdebian debian axios 2mo ago Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback…
CVE-2026-21388 low 2.5 2mo ago Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint
CVE-2026-5849 critical 9.8 9.8 2mo ago A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack …
CVE-2026-5841 critical 9.8 9.8 2mo ago A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can lead to path traversal…
CVE-2026-5836 low 2.4 2.4 2mo ago A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_product.php. The manipulation of the argument prod…
CVE-2026-5835 low 2.4 2.4 2mo ago A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Executing a manipulation of the argumen…
CVE-2026-5834 low 2.4 2.4 2mo ago A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name resul…
CVE-2026-5810 low 3.5 3.5 2mo ago A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argume…
CVE-2026-5806 low 3.5 3.5 2mo ago A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the argument postTitle leads to cro…
CVE-2026-39890 critical 9.5 2mo ago PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition Loading
CVE-2026-39510 low 2.7 2.7 2mo ago Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control S…
CVE-2026-39324 critical 9.5 FIX slesdebian debian 2mo ago Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization
CVE-2026-31789 critical 9.8 9.8 FIX slesdebian debian opensslgoogle 2mo ago Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a cr…
CVE-2026-33816 critical 9.8 9.8 FIX debian debian sles jackc 2mo ago Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVE-2026-33815 critical 9.8 9.8 FIX debian debian sles jackc 2mo ago Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVE-2026-34444 critical 10.0 10.0 debian debian scoder 2mo ago Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
CVE-2026-5735 critical 9.8 9.8 FIX debian debian sles mozilla 2mo ago Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exp…
CVE-2026-22679 critical 9.8 9.8 weaver 2mo ago Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows att…
CVE-2026-1114 critical 9.8 9.8 lollms 2mo ago In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT). This vulnerabili…
CVE-2025-65115 critical 9.8 9.8 hitachi 2mo ago Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2…
CVE-2026-5682 low 3.7 3.7 2mo ago A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation lea…
CVE-2026-35022 critical 9.8 9.8 anthropic 2mo ago Rejected reason: This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the -p flag behavior is documented in Anthropic's claude -h output with an explicit warning…
CVE-2026-35035 critical 9.5 2mo ago CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
CVE-2026-5668 low 2.4 2.4 2mo ago A flaw has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown part of the file /admin/Add%20notice/add%20notice.php. This manipu…
CVE-2026-34989 critical 9.0 9.0 ci4-cms-erp 2mo ago CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CVE-2026-5647 low 2.4 2.4 2mo ago A vulnerability was detected in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /admin/admin_feature.php of the component Add Product Page. The manipulation of the argum…
CVE-2026-5644 low 2.4 2.4 2mo ago A security flaw has been discovered in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Affected is an unknown function of the file /admin/Add%20notice/batch-notice…
CVE-2026-5643 low 2.4 2.4 2mo ago A vulnerability was identified in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This impacts an unknown function of the file /admin/Add%20notice/notice.php of th…
CVE-2026-31405 critical 9.8 9.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension header tables The ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] ta…
CVE-2026-5622 low 3.7 3.7 2mo ago A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functionality of the file foundations/core/packages/token/src/token.ts of the component J…
CVE-2026-35679 low 3.5 3.5 2mo ago Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was someti…
CVE-2026-5584 critical 9.8 9.8 fosowl 2mo ago A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py of the component query Endpoint. Such manipulatio…
CVE-2026-5574 critical 9.1 9.1 2mo ago A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/pa…
CVE-2026-5573 critical 9.8 9.8 2mo ago A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipulation of the argument cwd can lead to unrestricted…
CVE-2026-5570 critical 9.8 9.8 2mo ago A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginCB. This manipulation causes improper authenticatio…
CVE-2026-5569 critical 9.8 9.8 2mo ago A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper a…
CVE-2026-5568 low 3.5 3.5 2mo ago A vulnerability has been found in Akaunting up to 3.1.21. This issue affects some unknown processing of the component Invoice/Billing. The manipulation of the argument notes leads to cross site scrip…
CVE-2026-5562 critical 9.8 9.8 provectus 2mo ago A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint. The manipulation lea…
CVE-2026-5526 critical 9.8 9.8 2mo ago A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation result…
CVE-2026-32186 critical 10.0 10.0 2mo ago Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-28373 critical 9.6 9.6 macos macos stackfield 2mo ago The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export ca…
CVE-2026-23455 critical 9.1 9.1 FIX sles rheldebian debian 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit leng…
CVE-2026-23450 critical 9.8 9.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_…
CVE-2026-5463 critical 9.8 9.8 danmcinerney 2mo ago Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This break…
CVE-2026-32211 critical 9.1 9.1 2mo ago Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.
CVE-2026-33105 critical 10.0 10.0 2mo ago Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-26135 critical 9.6 9.6 2mo ago Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.
CVE-2026-33107 critical 10.0 10.0 2mo ago Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-32213 critical 10.0 10.0 2mo ago Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-5420 low 2.5 2.5 2mo ago A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown function of the file jRwTX.java of the component cats.goods.sort.sorting.games. …
CVE-2026-5413 low 3.7 3.7 2mo ago A vulnerability was identified in Newgen OmniDocs up to 12.0.00. Affected by this vulnerability is an unknown functionality of the file /omnidocs/GetWebApiConfiguration. The manipulation of the argum…
CVE-2026-5370 low 3.5 3.5 2mo ago Krayin CRM is vulnerable to Cross-site Scripting (XSS)
CVE-2026-5368 critical 9.8 9.8 projectworlds 2mo ago A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the…
CVE-2026-5360 low 3.7 3.7 free5gc 2mo ago A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack may be launched remotely. Thi…
CVE-2026-5334 critical 9.8 9.8 itsourcecode 2mo ago A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=edit&id=3 of the component Parameter Handler. This …
CVE-2026-5333 critical 9.8 9.8 defaultfuction 2mo ago A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/tools.php. The manipulation of the argument host res…
CVE-2026-5244 critical 9.8 9.8 FIX debian debian cesanta 2mo ago A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pu…
CVE-2026-5325 low 3.5 3.5 2mo ago A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects some unknown processing of the file /create-ticket.php of the component Create …
CVE-2026-34159 critical 9.8 9.8 FIX debian debian ggml 2mo ago llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthentica…
CVE-2026-34072 critical 9.8 9.8 fccview 2mo ago Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an authentication bypass in middleware allows unauthe…
CVE-2026-5310 low 2.5 2.5 2mo ago A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to use of hard-coded cryptograph…
CVE-2026-34430 critical 9.6 9.6 deerflow 2mo ago ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing re…
CVE-2026-5257 critical 9.8 9.8 code-projects 2mo ago A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /delstaffinfo.php of the component Parameter Handler. Such manipulati…
CVE-2026-5256 critical 9.8 9.8 code-projects 2mo ago A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modify.php of the component Parameter Handler. This manipulation of the argument…
CVE-2026-5254 low 3.5 3.5 2mo ago A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown functionality of the file /ui/app/components/AppJsonTreeView.vue of the component…
CVE-2026-5253 low 3.5 3.5 2mo ago A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageList.vue of the component edi…
CVE-2026-5252 low 3.5 3.5 2mo ago A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint. Performing a manipulation …
CVE-2026-5249 low 3.5 3.5 2mo ago A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulatio…
CVE-2026-5209 low 2.4 2.4 2mo ago A security vulnerability has been detected in SourceCodester Leave Application System 1.0. Affected by this issue is some unknown functionality of the component User Management Handler. Such manipula…
CVE-2026-0596 critical 9.5 2mo ago Mlflow: Command Injection when serving models with enable_mlserver=True
CVE-2026-5183 critical 9.8 9.8 2mo ago A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the file /goform/addRouting. Executing a manipulation of the argument dest can lead…
CVE-2026-5176 critical 9.8 9.8 2mo ago A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument provid…
CVE-2025-15379 critical 9.8 9.8 lfprojects 2mo ago MLflow Command Injection vulnerability
CVE-2025-15036 critical 10.0 10.0 lfprojects 2mo ago MLFlow path traversal vulnerability
CVE-2026-5037 low 3.3 3.3 FIX slesdebian debian 2mo ago A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c of the component mxmlIndexNew. Executing a manipulation of the argument tempr c…
CVE-2026-5035 critical 9.8 9.8 sherlock 2mo ago A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Parameter Handler. Such manipulation of the argument en…
CVE-2026-5034 critical 9.8 9.8 sherlock 2mo ago A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation…
CVE-2026-5033 critical 9.8 9.8 sherlock 2mo ago A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Parameter Handler. The …
CVE-2026-5030 critical 9.8 9.8 2mo ago A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipul…
CVE-2026-5020 critical 9.8 9.8 2mo ago A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The ma…
CVE-2026-5019 critical 9.8 9.8 carmelo 2mo ago A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file all-orders.php of the component Parame…
CVE-2026-5018 critical 9.8 9.8 carmelo 2mo ago A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the component Parameter Handler. Executing a manipulat…
CVE-2026-5017 critical 9.8 9.8 carmelo 2mo ago A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manip…
CVE-2026-4995 low 3.5 3.5 2mo ago A vulnerability was determined in wandb OpenUI up to 1.0. Affected by this vulnerability is an unknown functionality of the file frontend/public/annotator/index.html of the component Window Message E…